pcnsa question 123 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 123

What is the main function of the Test Policy Match function?

  • A. ensure that policy rules are not shadowing other policy rules
  • B. confirm that rules meet or exceed the Best Practice Assessment recommendations
  • C. confirm that policy rules in the configuration are allowing donning the correct traffic
  • D. verify that policy rules from Expedition are valid
Answer:

d

User Votes:
A
50%
B
50%
C 1 votes
50%
D
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

C. Confirm that policy rules in the configuration are allowing or denying the correct traffic: This is correct. The Test Policy Match function is used to simulate traffic against the existing security policy rules to see how that traffic would be handled, helping to verify that the rules are correctly configured.

sara123
1 month, 3 weeks ago

The Test Security Policy Match window enables you to enter a set of criteria directly from the web interface rather than from the CLI. After a test is executed, the criteria are evaluated against the current Security policy rules to determine if the simulated traffic matches an ex isting policy. After running the policy match and connectivity tests in the web interface, you can quickly and easily test connectivity to ensure that policy rules allow or deny the correct traffic, and t hose devices can connect to network resources such as WildFire ® or Log Collectors
[Palo Alto Networks]